What poor website and email security actually costs
Not our numbers. Every figure below is published by IBM, Verizon or the insurance industry, and linked. We have marked the ones ActiScore can check on a domain in about a second, and left the rest unmarked — because pretending a tool fixes something it does not touch is how a vendor loses a room.
The cost, when it happens
$4.99M
The global average cost of a data breach, across more than 600 organisations breached between March 2025 and February 2026.
IBM — Cost of a Data Breach Report 2026 · 2026 · figure reported via Help Net Security
247 days
Mean time to identify and contain a breach — eight months in which an attacker is already inside.
IBM — Cost of a Data Breach Report 2026 · 2026 · figure reported via Help Net Security
62%
Share of breaches involving the human element — someone clicking, trusting or being deceived rather than a firewall being defeated.
Verizon — Data Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI
ActiScore checks this: Whether your domain can be impersonated in the emails that deception arrives in — SPF, DKIM and DMARC.
39%
Share of breaches in which stolen credentials appear somewhere in the chain.
Verizon — Data Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI
31%
Share of breaches involving exploitation of a known vulnerability — software that had a fix available and had not been updated.
Verizon — Data Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI
ActiScore checks this: Whether your server announces its exact software version in its response headers, which tells an attacker which exploit to try first.
26%
Share of known exploited vulnerabilities that were fully remediated in 2025 — down from 38% the year before.
Verizon — Data Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI
$50,000
Median loss from a business email compromise, against $6.3 billion in reported losses overall.
Verizon — Data Breach Investigations Report 2026 · 2026 · figure reported via Keepnet
ActiScore checks this: Whether an attacker can send mail that appears to come from your own domain — the mechanism most invoice fraud starts with.
The cost before anything happens
This is the part most businesses have not caught up with. Cyber insurance underwriting stopped being a questionnaire and became a scan — and the things being scanned are externally visible, which means a broker, a competitor and an attacker can all see them too.
A line item
Email authentication now appears alongside MFA, endpoint detection and backups as a named factor in cyber insurance pricing and coverage availability. Applications ask specifically about DMARC policy, SPF configuration and DKIM key management.
AutoSPF — Email Authentication and Cyber Insurance: How Underwriters Are Pricing DMARC in 2026 · 2026
ActiScore checks this: Your SPF, DKIM and DMARC records, and whether the DMARC policy is enforcing or only watching.
Scanned, not asked
Carriers now run automated scans of an applicant’s external-facing infrastructure during underwriting — checking whether MFA is enforced, whether the email domain publishes DMARC, and whether software is patched.
AutoSPF — Email Authentication and Cyber Insurance 2026 · 2026
ActiScore checks this: The same externally visible posture an underwriter’s scan sees — before they see it.
40–100%
Premium increase reported for businesses that fail the technical audit, alongside coverage exclusions or outright denial into surplus lines at roughly triple the standard rate.
AutoSPF — Email Authentication and Cyber Insurance 2026 · 2026
Travelers v. ICS
A cyber policy was rescinded over the gap between the controls an applicant described and the controls actually running — firewall-only MFA voided a $1 million policy. The claim being genuine did not save it.
Reported in industry coverage of the case — Travelers Property Casualty Co. of America v. International Control Services · 2022, still cited in 2026 underwriting guidance
ActiScore checks this: What is actually running, which is the thing an application form cannot check about itself.
What this does and does not argue
A website audit does not prevent a breach. Nothing on this page claims it does, and a vendor telling you otherwise is selling you something.
What it does is answer, in seconds and without permission, three questions an underwriter now asks and most owners cannot answer about themselves: can anyone send email as this domain, is the certificate about to lapse, and does the server announce which software version to attack. Those are findings, not opinions — and each one is verifiable with a single command, which is why a prospect argues with the fix rather than with the number.
The gap between what a business believes about its own security posture and what is actually published to the internet is the whole conversation. Travelers v. ICS is what that gap costs when it goes untested.
Sources
- IBM — Cost of a Data Breach Report 2026
- Help Net Security — Summary of Cost of a Data Breach Report 2026
- Verizon — Data Breach Investigations Report 2026
- Abnormal AI — Summary of Data Breach Investigations Report 2026
- Keepnet — Summary of Data Breach Investigations Report 2026
- AutoSPF — Email Authentication and Cyber Insurance: How Underwriters Are Pricing DMARC in 2026
Every figure on this page is published by someone else and linked. We have no customer case studies yet because we have no customers yet, and an invented one would be the exact thing this product exists to catch.